CVE-2025-12815: Aws Research And Engineering Studio Res
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users should upgrade to version 2025.09 or above.
Affected products
- Aws Research And Engineering Studio Res
Published 2025-11-06. Last modified 2026-10-07.